Skip to content

CVE-2026-5704 on CTRL-OS 26.05

Aliases: CVE-2026-5704

Packages: gnutar

Status: Plausible

Advisory Information

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Updates

2026-06-03 19:51 CEST

Metadata changes:

  • Status for package gnutar: “Plausible

2026-06-02 00:01 CEST

Metadata changes:

  • Status for package gnutar: “New